[CLSA-2026:1786357391] Fix CVE(s): CVE-2026-59850
Type:
security
Severity:
Important
Release date:
2026-08-10 10:23:21 UTC
Description:
* SECURITY UPDATE: use-after-free in channel_rcv_data() when a DATA packet is received on a channel already closed by the remote peer - debian/patches/CVE-2026-59850.patch: reject DATA packets on channels flagged SSH_CHANNEL_FLAG_CLOSED_REMOTE in src/channels.c - CVE-2026-59850
CVEs fixed:
Updated packages:
  • libssh-4_0.6.3-4.3ubuntu0.6+tuxcare.els6_amd64.deb
    sha:5b38fa660f7e281af41ae1a952c36ee4a77f307b
  • libssh-dev_0.6.3-4.3ubuntu0.6+tuxcare.els6_amd64.deb
    sha:d22c2c1233d1787207f92062fd4a10bfa611cae5
  • libssh-doc_0.6.3-4.3ubuntu0.6+tuxcare.els6_all.deb
    sha:b08d9883ac3ffe72991a9614a13c9828046155d3
  • libssh-gcrypt-4_0.6.3-4.3ubuntu0.6+tuxcare.els6_amd64.deb
    sha:91e57e545d9930009ae70e0c19522147e88b0ed4
  • libssh-gcrypt-dev_0.6.3-4.3ubuntu0.6+tuxcare.els6_amd64.deb
    sha:1dd8632ea34417957459985a9aba314dd4f90b1b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.